VDB
Sign up
LOW

GHSA-724c-6vrf-99rq

Sensitive Data Exposure in loopback

Quick fix

GHSA-724c-6vrf-99rq — loopback: upgrade to the fixed version with the command below.

npm install loopback@2.42.0

Details

Versions of `loopback` prior to 3.26.0 (3.x) and 2.42.0 (2.x) are vulnerable to Sensitive Data Exposure. Invalid API requests to the login endpoint may return information about the first user in the database. This can be used alongside other attacks for credential theft.

## Recommendation

If you're using `loopback` 3.x upgrade to version 3.26.0 or later. If you're using `loopback` 2.x upgrade to version 2.42.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/loopback
Introduced in: 0Fixed in: 2.42.0
Fixnpm install loopback@2.42.0
npm/loopback
Introduced in: 3.0.0Fixed in: 3.26.0
Fixnpm install loopback@3.26.0

References